Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0379 — Detect Evil Twin Wi-Fi Access Points on Network Devices
DET0379

Detect Evil Twin Wi-Fi Access Points on Network Devices

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1069 Analytic 1069
Network Devices

Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs.

WLANLogs:Association Multiple APs advertising the same SSID but with different BSSID/MAC or encryption type NSM:Flow Probe responses from unauthorized APs responding to client probe requests networkdevice:syslog Failed authentication requests redirected to non-standard portals
[KnownSSIDs] Baseline of authorized SSIDs; deviations may indicate rogue AP.
[AllowedBSSIDs] Whitelist of BSSID/MAC addresses mapped to corporate SSIDs.
[SignalStrengthThreshold] Used to flag unusually strong signals from unexpected APs.
[CaptivePortalDomains] Trusted login domains; unrecognized portals may be malicious.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0379
STIX ID
x-mitre-detection-strategy--b376d299-69ef-444a-8ba1-15a6c7049605
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.